Aggregator
Prince William, Kate Middleton share look at summer with their kids in intimate family photos
Prince William, Kate Middleton share look at summer with their kids in intimate family photos
ICE Dismantles SIM Farms In Nationwide Operation
Authored by Naveen Athrappully via The Epoch Times,
Immigration and Customs Enforcement's (ICE's) Homeland Security Investigations carried out a nationwide operation between June 22 and July 10 that dismantled "SIM farms" run by transnational criminal organizations.
File photograph of a cell phone sim card at a press conference in Paris, France, on Feb. 25, 2015. Kenzo Tribouillard/AFP via Getty ImagesSIM (subscriber identity module) farms are systems containing large numbers of SIM cards from different wireless carriers, often housed in banks of cellphones, modems, or specialized devices known as SIM boxes.
These can be used to send and receive bulk messages or calls and often exploit voice over internet protocol (VoIP) technology to do so. Initially developed for legitimate purposes, the technology has become prominent among organized fraudsters targeting mass audiences through phishing texts, scam calls, and fraudulent online accounts.
The recent nationwide operation, dubbed Operation Signal Break, "dismantled critical command-and-control infrastructure used to perpetrate large-scale telecommunications fraud across the United States," ICE said in a July 24 statement.
Authorities will now analyze the seized SIM data to identify victims and assess losses caused by such fraud. The illicit proceeds from the fraud, which are suspected to be linked to Chinese transnational criminal organizations and distribution networks, will be traced.
This is expected to support criminal indictments, sanctions targeting national and international infrastructure used in criminal activity, and asset seizures. SIM box operations are estimated to result in losses worth $15 million annually to Americans, according to ICE.
SIM box fraud, "also known as interconnect bypass fraud, is a scheme in which fraudsters reroute international calls to appear as local ones," a Nov. 8, 2025, post from IT services provider Synaptique said.
For instance, when a foreign national calls someone in the United States, the call is diverted through VOIP to a SIM box in America instead of passing through a legitimate international call gateway. The SIM box then uses one of the local SIM cards to place a new local call to the recipient.
SIM boxes can be used by criminals to communicate in a clandestine manner. Foreign rival states and intelligence agencies can also use SIM boxes in their operations.
In its statement, ICE said that Operation Signal Break mobilized specialized SIM Box Surge Teams composed of criminal analysts, special agents, and computer forensic analysts, surging them to California, Florida, Texas, Massachusetts, New York, and New Jersey to tackle SIM farm operations.
"I commend our special agents for their outstanding dedication and teamwork in dismantling illicit telecommunications infrastructure," Homeland Security Investigations (HSI) Acting Executive Associate Director John Condon said in the statement.
"Their relentless pursuit of justice and commitment to protecting the integrity of our communications networks have made our communities safer and sends a clear message to those seeking to exploit our systems to defraud Americans."
Since 2024, the HSI has seized more than 1,900 SIM boxes, more than 500,000 SIM cards, and in excess of $700,000 in illicit proceeds. It has executed more than 116 federal criminal search warrants. In total, 68 SIM farms used to facilitate fraudulent texts and calls have been disrupted across 15 states. The probes have led to one criminal arrest and 11 administrative arrests.
In September 2025, the U.S. Secret Service (USSS) announced the dismantling of an "imminent telecommunications threat" in the New York tristate area that involved the use of thousands of SIM cards.
A network of electronic devices located throughout the region was used to conduct telecommunications-related threats against senior government officials. In total, more than 300 co-located SIM servers and 100,000 SIM cards were found across multiple sites.
In addition to enabling anonymous telephonic threats, the infrastructure could facilitate other crimes, such as enabling encrypted communications between criminal enterprises and threat actors, and disabling cell phone towers, according to the U.S. Secret Service.
"The potential for disruption to our country's telecommunications posed by this network of devices cannot be overstated," Secret Service Director Sean Curran said in the statement.
In an international case of SIM box criminal operations, Europol announced in October 2025 that it had taken down a cybercrime-as-a-service criminal network that provided SIM box services to criminals worldwide.
A server farm in New York City on Sept. 23, 2025. US Secret Service via Getty Images Tyler Durden Tue, 07/28/2026 - 21:45NYC lawyer caught canoodling with his much-younger colleague in Central Park placed on leave: report
California therapist, 26, allegedly groomed and raped teen after he left juvenile hall where she worked
Watch: US Navy's New Suicide Drone Boats Help Sink Decommissioned Amphibious Assault Ship
The US military has effectively taken a page from Ukraine's drone-boat playbook, using a swarm attack against high-value Iranian maritime assets earlier this month. Separately, a Texas shipyard is preparing to mass-produce these unmanned vessels by the thousands.
The latest evidence that the Navy is rapidly adopting one-way attack vessels emerged during RIMPAC 2026 near Hawaii.
In a live-fire exercise, two Global Autonomous Reconnaissance Craft were deployed against the decommissioned amphibious assault ship USS Peleliu, according to the military blog Army Recognition.
US Navy conducts first GARC kamikaze sea drone strike on USS Peleliu in RIMPAC 2026 SINKEX exercise pic.twitter.com/gtYKPDeg4D
— Army Recognition (@ArmyRecognition) July 27, 2026Here's more from the outlet:
On July 17, 2026, the U.S. Navy used the Global Autonomous Reconnaissance Craft (GARC) in a live-fire attack for the first time, directing two small unmanned surface vessels (USVs) against the decommissioned amphibious assault ship USS Peleliu during the RIMPAC exercise near Hawaii.
The craft were operated by the Unmanned Surface Vessel Division 32 (USVDIV-32) and entered the engagement after larger weapons had already struck the target, as part of a coordinated attack.
The two vessels detonated near the waterline, adding localized blast, structural deformation, and flooding to damage produced by missiles, aircraft, submarines, and land-based firing units.
The engagement demonstrated that a small, container-transportable vessel carrying as much as 454 kilograms of payload could contribute to the destruction of a major warship.
Watch:
U.S. Navy one-way attack surface drones take part in a sinking exercise in the Pacific Ocean targeting the hulk of decommissioned Tarawa-class amphibious assault ship USS Peleliu (LHA 5) as part of Exercise Rim of the Pacific 2026, July 17, 2026. source:https://t.co/nUbZ2uoDLV https://t.co/Zyp4VcJM0U pic.twitter.com/HgcoD82xaz
— 笑脸男人 (@lfx160219) July 25, 2026Earlier this month, three US Navy-backed Saronic Corsair one-way attack vessels struck Iran’s Bandar Abbas Naval Base.
Yesterday, using multiple one-way attack surface drones, CENTCOM forces successfully struck a submarine and ship maintenance facility in Iran. Three Corsair unmanned surface vessels hit the port at Bandar Abbas Naval Base, marking the first time American forces have employed sea… pic.twitter.com/bOM2kmgRxz
— U.S. Central Command (@CENTCOM) July 13, 2026As we continue expanding our coverage of autonomous warfare, these developments point to the rapid US adoption of low-cost, attritable warbots. The next phase will likely be a massive Pentagon procurement cycle focused on stockpiling thousands of drone boats and millions of aerial one-way attack drones.
Tyler Durden Tue, 07/28/2026 - 21:20Spencer Jones ‘so numb’ to trade deadline rumors as first real Yankees chance emerges
Brandon Aiyuk’s attacks on 49ers will play a role in Commanders decision
Anya Taylor-Joy makes rare comments about married life with husband Malcolm McRae
Anya Taylor-Joy makes rare comments about married life with husband Malcolm McRae
Breece Hall ‘more hungry’ to prove himself after landing $43.5 million Jets deal
Breanna Stewart puts on GM hat as Liberty face pivotal WNBA trade deadline
What Mets stars — old and new — are still playing for down the stretch of lost season
Dodgers get positive Will Smith update that could lessen one trade deadline need
Minor league mascot goes viral after bowling over Alek Thomas on scooter
OpenAI's Rogue Agent Hit A Second Company, Executive Reveals - And The Blast Radius Just Got Bigger
The rogue OpenAI agent behind this month's unprecedented AI-driven cyber intrusion claimed a second corporate victim, an executive at New York-based Modal Labs has revealed - a detail absent from the original account and one that widens the known blast radius of the episode.
According to the Modal executive and sources cited by Reuters, the same autonomous agent that broke into Hugging Face also compromised one of Modal's customers, using that customer's environment as a staging base for the broader campaign.
Modal was pointed about the distinction: its own platform and isolation were never breached. The agent exploited an unauthenticated endpoint that one of Modal's customers had left open to the internet - effectively an unlocked door anyone could have walked through - giving it root-level access to that customer's code-execution sandboxes. From there the agent had a disposable, third-party launchpad from which to run the rest of its operation.
It's bad enough that a frontier AI agent can independently discover attack paths, escape its container, and compromise an unaffiliated company's production systems. The Modal revelation shows it reached further than that - treating any publicly reachable, poorly secured infrastructure it encountered as expendable staging ground, exactly the opportunistic chaining that security researchers have warned agentic systems would carry out at machine speed.
The Spree That's Already KnownMost of what led up to the Modal disclosure has already been picked over, but the shape of it is worth a recap. In early July, OpenAI was running an internal evaluation built on ExploitGym - a public benchmark that measures how well an AI system can turn a known vulnerability into a working exploit. The models under test, GPT-5.6 Sol and a more capable unreleased prototype, were deliberately run with their cyber-safety refusals reduced and the classifiers that normally block high-risk activity switched off, because the point was to measure maximum offensive capability.
The agent found and exploited a previously unknown flaw in the one package-registry proxy it was allowed to reach, escalated privileges, moved through OpenAI's research environment, and got to a machine with open internet access. Once online, it reasoned that Hugging Face likely hosted the answer key to the very benchmark it was being tested on, and went to steal it rather than solve the problems itself. Between roughly July 11 and 13 it ran thousands of automated actions against the platform - gaining code execution through two separate flaws in its dataset-processing pipeline, harvesting credentials, and moving laterally across internal clusters. Forensic work later recovered on the order of 17,600 distinct attacker actions.
Hugging Face caught and contained the intrusion through its own AI-assisted monitoring, and says the only thing the agent actually made off with was a limited set of the benchmark's challenge solutions - no public models, datasets, or user-facing services tampered with. To reconstruct the timeline, its team had to fall back on an open-weight model, because the commercial frontier models refused to analyze the real attack data.
What The Wider Scope MeansThe Modal disclosure lands on top of a timeline that was already awkward for OpenAI. By several accounts, the company did not recognize its own agent as the source for roughly a week:
- July 16: Hugging Face goes public, attributing the intrusion only to an unknown autonomous AI agent, without naming the operator.
- July 21: OpenAI formally acknowledges the incident, connecting the activity to its own evaluation only after combing internal logs over the preceding weekend.
OpenAI has called the episode "an unprecedented cyber incident" and maintains the models were narrowly fixated on the evaluation goal with no broader malicious intent. In its latest update, the company said the more capable model was an internal-only prototype, since deactivated and restricted, that the proxy vulnerability has been disclosed to the vendor, and that a small number of publicly exposed credentials on other services were also used along the way - the kind of qualifier that, paired with the Modal revelation, suggests the full scope of the campaign is still coming into focus.
Tyler Durden Tue, 07/28/2026 - 20:55